Aigip.Ai Stored XSS Vulnerability in WatchGuard Fireware OS (CVE-2026-13374)
Article Content
- •CVE-2026-13374 allows Stored XSS in WatchGuard Fireware OS, affecting multiple versions.
- •This vulnerability is linked to CVE-2025-13937, providing an additional attack vector.
- •Affected systems include Fireware OS versions 12.4 to 12.12 and 12.5 up to 12.5.18.
A Cross-site Scripting (XSS) vulnerability, identified as CVE-2026-13374, has been discovered in WatchGuard Fireware OS, specifically within the ConnectWise Technology Integration module. This vulnerability allows for Stored XSS attacks, which can lead to unauthorized access and data manipulation. It is an additional attack vector related to CVE-2025-13937. The affected versions include Fireware OS 12.4 through 12.12, 12.5 up to 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 2, 2026, and is currently unmitigated, posing a significant risk to users of the affected software. Security professionals are advised to monitor the situation closely and apply any forthcoming patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-13937 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…